Courseiva
hardMultiple Select

CCSP Practice Question: A cloud security architect is designing a…

A cloud security architect is designing a DevSecOps pipeline for a multi-cloud environment. Which THREE practices should be included to ensure security is integrated early? (Select THREE)

⚠ Common exam trap

The CCSP exam often tests the concept of 'shift-left' by including late-stage security activities (like post-deployment scanning or production DAST) as distractors, tempting candidates who confuse 'security testing' with 'early integration'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scanning dependencies for known vulnerabilities in the CI pipeline

Option A is correct because scanning dependencies for known vulnerabilities in the CI pipeline (e.g., with SCA tools like Dependabot, Snyk, or OWASP Dependency-Check) shifts detection of vulnerable third-party libraries to the earliest build stage, before artifacts are promoted. Option D is correct because IaC security scanning on Terraform templates (e.g., with Checkov, tfsec, or Terrascan) catches misconfigurations such as public S3 buckets or overly permissive security groups before any infrastructure is provisioned. Option E is correct because performing SAST scans in the IDE or during pull requests (e.g., with SonarQube, Semgrep, or CodeQL) gives developers immediate feedback on insecure code patterns at the point of authorship, which is the earliest possible integration point. Option B does not belong because scanning container images only after production deployment is a reactive, post-deployment control rather than an early-shift-left practice. Option C does not belong because DAST against production is a late-stage, runtime test that exercises a live environment and cannot prevent defects from reaching production.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Scanning dependencies for known vulnerabilities in the CI pipeline

    Why this is correct

    Scanning dependencies in CI detects known vulnerabilities in third-party libraries before artefacts are built, shifting remediation left. This satisfies the multi-cloud DevSecOps requirement by catching supply-chain flaws early, when fixes are cheaper and before code reaches deployment.

  • ✗

    Scanning container images after they are deployed to production

    Why it's wrong here

    Scanning images after deployment detects vulnerabilities only once workloads are already running in production, so flaws are not caught before release. It is tempting because runtime scanning covers the exact artefacts deployed and catches drift, which suits continuous monitoring of long-lived production registries rather than shift-left gating.

  • ✗

    Running DAST against the production environment

    Why it's wrong here

    Running DAST against production tests a live environment rather than gating code before release, and it risks corrupting real data; early integration requires testing in the pipeline against non-production targets. It appeals because production is the most realistic target, which suits periodic assurance of an already-deployed application.

  • ✓

    Running IaC security scanning on Terraform templates before deployment

    Why this is correct

    Scanning Terraform templates before deployment catches misconfigurations such as public buckets or permissive security groups while infrastructure is still declarative code. This satisfies the early-integration requirement by preventing insecure cloud resources rather than detecting them after provisioning.

  • ✓

    Performing SAST scans in the IDE or during pull requests

    Why this is correct

    SAST in the IDE or during pull requests analyses source code for flaws before merge, giving developers immediate feedback. This satisfies the requirement to integrate security early by blocking vulnerable code at authoring time, ahead of build and deployment stages.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.